Akira, LockBit actively searching for vulnerable Cisco ASA devices
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2020-3259 | Unauthenticated Memory-Disclosure Flaw in Cisco ASA and FTD Web Services CVE-2020-3259 is an information-disclosure vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software, caused by a buffer-tracking error when the device parses invalid URLs. An unauthenticated, remote attacker can trigger it by sending a crafted GET request to the web services interface, which allows retrieval of the device's memory contents and disclosure of confidential information. Only devices with specific AnyConnect and WebVPN configurations are affected, but those configurations are common on ASA/FTD firewalls deployed as enterprise edge and remote-access VPN gateways. Exploitation is confirmed in the wild: CISA added the bug to its Known Exploited Vulnerabilities catalog on 2024-02-15 with known ransomware use, and the Akira ransomware group (which the FBI says has extorted $42 million across roughly 250 attacks since March 2023) is actively exploiting it, with LockBit also scanning for vulnerable Cisco ASA devices. EPSS assigns a 71.8% probability of exploitation within 30 days, and no public proof-of-concept code is known. Do: Upgrade affected ASA and FTD devices to the fixed releases listed in Cisco's security advisory for CVE-2020-3259; if patching is delayed, disable or restrict the web services interface (WebVPN/AnyConnect) to trusted source networks. Per the CISA KEV required action, apply vendor mitigations or discontinue use where mitigations are unavailable. Prioritize internet-facing VPN gateways and hunt for exploitation indicators (anomalous GET requests to the web services interface) given active Akira and LockBit targeting. | 7.5 | 72% | KEV ransomware |
| mass~100,000+ internet-exposed ASA/FTD devices with the web services (WebVPN/AnyConnect) interface enabled | |
| CVE-2020-3580 | Cross-Site Scripting in Cisco ASA and FTD Web Services Interface CVE-2020-3580 is a cross-site scripting (XSS) flaw caused by insufficient validation of user-supplied input in the web services interface of Cisco ASA and Firepower Threat Defense (FTD) software. An unauthenticated, remote attacker can exploit it by persuading a user of the web interface to click a crafted link, which then executes arbitrary script code in the context of the interface or exposes sensitive browser-based information such as session data. Only devices running specific AnyConnect and WebVPN configurations are affected, so not every ASA/FTD deployment is vulnerable. The flaw is under active exploitation: it is in CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03) with known ransomware use, a public PoC exploit has driven scanning, and groups such as Akira and LockBit are actively searching for vulnerable Cisco ASA devices. Do: Apply updates per the vendor's instructions (Cisco's advisory lists the fixed ASA/FTD releases), prioritizing internet-facing devices since ransomware operators (Akira, LockBit) are actively scanning. Check whether the web services interface (AnyConnect/WebVPN) is enabled, as only those configurations are vulnerable, and restrict internet access to the device's management/web interface where possible. Treat as urgent given its KEV listing and known ransomware use. | 6.1 | 86% | KEV ransomware |
| mass≈100,000–1,000,000 internet-exposed ASA/FTD appliances (Cisco ASA is among the most commonly exposed edge firewall/VPN platforms in public internet scans) |
Full article336 words · extracted from helpnetsecurity.com · click to collapse
Akira and Lockbit ransomware groups are trying to breach Cisco ASA SSL VPN devices by exploiting several older vulnerabilities, security researcher Kevin Beaumont is warning.

They are targeting vulnerabilities for which patches have been made available in 2020 and 2023. “But the problem is nobody has complete visibility of what exploits actually exist,” he added, and advised admins to upgrade to the latest ASA release on all devices that have the AnyConnect SSL VPN feature enabled on the device’s (internet-exposed) interface.
Old vulnerabilities haunt many organizations
Cisco ASA devices are widely deployed in organizations of all sizes, and are regularly targeted by attackers (including ransomware groups) via unpatched vulnerabilities, credential stuffing and targeted brute-force attacks.
PoCs for patched vulnerabilities surface often, making the attackers’ work easier, but they are also either creating their own exploits or buying them from somewhere: Truesec researchers have recently flagged Akira‘s likely (but not definitely confirmed) exploitation of CVE-2020-3259, for which there is no known public exploit.
And though an exploit for CVE-2020-3580, a cross-site scripting (XSS) vulnerability affecting Cisco ASA and FTD devices, was leveraged by attackers in 2021, ransomware groups are obviously hoping that many organizations are VERY slow to patch.
“I’ve just been looking at data from GreyNoise and other firms. There has been a significant uptick in scanning for Cisco AnyConnect VPN devices,” Beaumont also noted on Wednesday.
“95% of the IPs doing it are tagged as malicious, not researchers or IoT search engines,” he added. “Many IPs overlap with CitrixBleed exploitation a few months ago by ransomware groups.”
So, you’ve now been warned: get patching (if you haven’t already) or risk being ransomed.
UPDATE (February 22, 2024, 03:55 a.m. ET):
Cisco has updated the security advisory for CVE-2020-3259 to say: “In February 2024, the Cisco Product Security Incident Response Team (PSIRT) became aware of additional attempted exploitation of this vulnerability in the wild. Cisco continues to strongly recommend that customers upgrade to a fixed software release to remediate this vulnerability.”
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2024/02/08/ransomware-cisco-asa-vulnerabilities/